www.securityweek.com 8/21/2026, 9:30:45 AM · external

North Korean hackers breach Rust supply chain via crate arrayref

North Korean hackers breach Rust supply chain via crate arrayref
Developing story vulnerability 2 articles tracked
North Korean hackers compromise Rust crate arrayref in supply chain attack
CyberSIXT Evidence Panel
Primary Source blog.rust-lang.org
Threat Actor

A new supply chain attack linked to North Korean hackers targeted the Rust programming ecosystem, specifically a popular crate called 'arrayref.' The malicious version, 'arrayref@0.3.10,' was published from the original maintainer's account on August 20, containing code to fetch a harmful binary. Other compromised crates were linked to the attack, and the Rust Security Response Team quickly removed the malicious packages.

The attack is attributed to the North Korean threat actor Sapphire Sleet, who also executed earlier supply chain attacks on the NPM registry. No evidence of exploitation has been found, and the original author of the 'arrayref' crate is likely compromised.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline